Falhas do tipo CWE-306

2.627 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2024-27169HIGHLack of authenticationEPSS 0.3%CVE-2026-11848HIGHIEI Integration Corp| iRM-IEI Remote Management - Missing AuthenticationEPSS 0.3%CVE-2026-11539MEDIUMIBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesEPSS 0.3%CVE-2025-55070MEDIUMLack of MFA enforcement in WebSocket connectionsEPSS 0.3%CVE-2026-10283MEDIUMBottelet DaybydayCRM Setting missing authenticationEPSS 0.3%CVE-2024-26519CRITICALAn issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to theEPSS 0.3%CVE-2026-44649CRITICALSillyTavern: Authentication Bypass via SSO Header InjectionEPSS 0.3%CVE-2025-3498CRITICALUnauthenticated modification of Radiflow iSAP Smart Collector configurationEPSS 0.3%CVE-2025-63896HIGHAn issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject EPSS 0.3%CVE-2025-62607MEDIUMNautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URLEPSS 0.3%CVE-2026-46999HIGHVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). SupportEPSS 0.3%CVE-2026-31944HIGHLibreChat MCP OAuth callback does not validate browser session — allows token theft via redirect linkEPSS 0.3%CVE-2020-26192HIGHDell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non-admin user with either ISI_PRIV_LOGIN_CEPSS 0.3%CVE-2026-60705HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.3%CVE-2024-10649MEDIUMUnauthenticated File Upload in wandb/openuiEPSS 0.3%CVE-2020-3335MEDIUMCisco Application Services Engine Software Authorization VulnerabilityEPSS 0.3%CVE-2025-10772MEDIUMhuggingface LeRobot ZeroMQ Socket lekiwi_remote.py missing authenticationEPSS 0.3%CVE-2026-50136HIGHBudibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentialsEPSS 0.3%CVE-2026-28485HIGHOpenClaw 2026.1.5 < 2026.2.12 - Missing Authentication in Browser Control HTTP EndpointsEPSS 0.3%CVE-2026-47038LOWVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0EPSS 0.3%